Security Advisory

CVE-2012-1180

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2012-04-17 21:00:00
Last updated 2024-08-06 18:53:35
Assigner redhat
State PUBLISHED

Description

Use-after-free vulnerability in nginx before 1.0.14 and 1.1.x before 1.1.17 allows remote HTTP servers to obtain sensitive information from process memory via a crafted backend response, in conjunction with a client request.